[hosted.weblate.org]Account Takeover

Disclosed: 2017-05-17 14:09:10 By 0xspade To weblate
Low
Vulnerability Details
Hello Team, **Steps to Reproduce:** * Go to Login Page * Reset Your Password by Clicking `Reset it`. * Put your email and answer the captcha. * Go to your email and click your reset Link. * You dont need to Change Your Password because you'll be logged in. **Scenario** Victim forgot to logout his/her Email Account on a Cafe/Internet Renting Shops. The Attacker Click the Reset Password link and because that Improper InValidation of Session on Password Reset Links lies in there. Attacker can gain access to Victim's Account. Let me know if you need more information. Best Regards,
Actions
View on HackerOne
Report Stats
  • Report ID: 223637
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report